CVE-2026-56365
LOWImageMagick - Memory Leak in PNG Encoder via MNG Image Writing
Title source: cnaDescription
ImageMagick before 7.1.2-19 contains a memory leak vulnerability in the PNG encoder when writing MNG images. Attackers can trigger the encoder failure condition to exhaust memory resources and cause denial of service.
References (2)
Core 2
Core References
Third Party Advisory third-party-advisory
VulnCheck Advisory: ImageMagick - Memory Leak in PNG Encoder via MNG Image Writing
https://www.vulncheck.com/advisories/imagemagick-memory-leak-in-png-encoder-via-mng-image-writing
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-x928-4434-crqj)
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-x928-4434-crqj
Scores
CVSS v3
3.7
EPSS
0.0027
EPSS Percentile
19.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-401
Status
published
Products (5)
ImageMagick/ImageMagick
< 6.9.13-44
imagemagick/imagemagick
< 6.9.13-44
ImageMagick/ImageMagick
< 7.1.2-19
ImageMagick/ImageMagick
6.9.13-44
ImageMagick/ImageMagick
7.1.2-19
Published
Jun 30, 2026
Tracked Since
Jul 01, 2026